PolicyKit
PolicyKit is an application framework that acts as a negotiator between the unprivileged
user session and the privileged system context. Whenever a process from the user session
tries to carry out an action in the system context, PolicyKit is queried. Based on its
configuration—specified in a so-called "policy"—the answer could be "yes", "no", or
needs authentication. Unlike classical privilege authorization programs such
as sudo, PolicyKit does not grant root permissions to an entire process, following the
"least privilege" concept.
9.1 Available Policies and Supported
Applications
At the moment, not all applications requiring privileges make use of PolicyKit. In the
following the most important policies available on SUSE® Linux Enterprise Desktop
are listed.
PulseAudio
Set scheduling priorities for the PulseAudio daemon
smppd
Control dial connections
9
PolicyKit
81
Need help?
Do you have a question about the LINUX ENTERPRISE DESKTOP 11 - SECURITY GUIDE 17-03-2009 and is the answer not in the manual?